Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the use of the wevtutil.exe utility to clear the Microsoft-Windows-Defender/Operational event log, a technique used by adversaries to disrupt security monitoring and hide malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
004
Detects the creation of .lnk files within the user startup directory. The rule flags suspicious activity by monitoring for specific file names often associated with the StealC information stealer, or when these files are created by common scripting hosts like PowerShell, WScript, or CScript.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
004
Detects instances where common browser credential and cookie storage files (Login Data, Cookies) for Google Chrome or Microsoft Edge are accessed by non-browser processes such as PowerShell, csc.exe, or the Search Indexer. This behavior is highly indicative of credential theft or session hijacking attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
004
Detects the execution of processes that contain command-line arguments indicative of debugger evasion techniques, such as checking for the presence of a debugger using functions like 'IsDebuggerPresent' or 'CheckRemoteDebuggerPresent'. This is commonly associated with malware attempting to evade dynamic analysis in sandboxes or by security researchers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
004
This rule detects attempts to clear Windows Event Logs using the 'wevtutil.exe' command-line utility or by identifying the generated Windows Security Event ID 1102 (Audit log was cleared). It tracks multiple instances of log clearing to identify suspicious bulk log deletion activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
104
Detects execution of the Windows diskpart utility using a script file, initiated by a process with a name ending in _win64.exe. This pattern is commonly used in malicious scripts for disk manipulation or inhibiting system recovery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
004
Detects execution of the Windows diskpart utility using a script file, initiated by a process with a name ending in _win64.exe. This pattern is commonly used in malicious scripts for disk manipulation or inhibiting system recovery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
004
Detects the use of .NET reflection and assembly loading techniques within PowerShell or C# compiler (csc.exe) command lines. Attackers frequently use these methods to load malicious payloads directly into memory, bypassing disk-based detection mechanisms. The rule looks for the combination of reflection-related namespaces/methods and indicators of obfuscation or encoding such as Base64 strings, Gzip compression, and decryption routines.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
104
This rule detects potential credential theft by monitoring for file access (creation, modification, or renaming) to common web browser sensitive files (Login Data or Cookies) followed by an outbound network connection from the same process within a 10-minute window. This behavior often indicates an adversary attempting to exfiltrate browser-stored credentials or session cookies.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
104
Detects instances where PowerShell initiates process injection behaviors, specifically targeting common user-facing applications such as browsers (chrome.exe, msedge.exe), build tools (csc.exe), or indexing services (SearchIndexer.exe). The rule identifies memory allocation and thread manipulation activities often associated with reflective code injection or memory-based payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
104
Detects the execution of git checkout commands initiated by known AI-powered coding assistants or CLI tools. This behavior may indicate an AI agent or automated script interacting with source code repositories in an unexpected or potentially unauthorized manner.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
204
This rule detects potentially suspicious Git checkout operations initiated by AI coding assistant processes (such as Copilot, Claude, or Gemini). It looks for cases where these assistants execute a 'git checkout' command containing a specific commit hash (40 characters), followed by a secondary event where the git output indicates an 'ambiguous refname' error. This pattern may suggest an attempt by an AI tool to manipulate repository state or checkout arbitrary objects, potentially related to unauthorized code injection or malicious repository interaction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
004
Detects a git checkout to a specific SHA followed by a git rev-parse HEAD verification command within AI coding assistant plugin directories (e.g., claude, codex, copilot, gemini). This pattern is monitored to identify potential supply chain compromises where a working tree might be silently substituted during plugin installation or updates.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
004
Detects the execution of git-related operations (fetch, pull, clone) as child processes of common AI coding agent binaries. This pattern is indicative of potential unattended or malicious background plugin auto-updates, which could be leveraged for 'Plugin4Shell' style zero-click plugin distribution attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
004
This rule detects network connections from internal devices to known SpiceRAT Command and Control (C2) infrastructure IPs. The detection filters for successful connections on common ports (80, 443) that meet a volume threshold, indicating potential ongoing beaconing or communication with malicious infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
002
Detects anomalous activity where an AI coding assistant process reads sensitive local credential files (such as .env, .aws/credentials, or SSH keys) followed by an outbound network connection to a destination not associated with known package registries or AI provider APIs. This pattern is indicative of potential prompt-injection attacks targeting autonomous AI coding tools to exfiltrate developer secrets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
000
Detects the execution of binaries or scripts named with keywords related to AI agent plugins (e.g., 'skill', 'plugin', 'mcp-server') from potentially untrusted locations like Downloads or Temp folders. The rule further correlates this execution with post-exploitation indicators such as persistence establishment (registry keys, scheduled tasks, launch agents) or outbound network activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
000
Detects a rapid, multi-stage intrusion sequence on a single host involving discovery, lateral movement, and high-volume file modifications. The rule identifies anomalous behavior where diverse reconnaissance and lateral movement commands are executed within a compressed timeframe, characteristic of automated or LLM-driven orchestration of ransomware operations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
000
Detects the installation of AI agent-related packages (npm, pip, etc.) followed shortly by unauthorized access to sensitive files or credential stores on the same host. This pattern is indicative of a malicious or 'poisoned' AI agent tool performing credential theft or unauthorized exfiltration of sensitive system data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
000
Detects the obfuscated first-stage JavaScript payload sharedLoad.min.js dropped by the malicious npm indexed-btree package, identified by string-array encoding and self-checksumming array rotation obfuscation patterns
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
002
Detects the sharedLoad.min.js obfuscated first-stage loader dropped by the malicious npm indexed-btree package, triggered via BTree.prototype.set to evade static/taint-analysis scanners
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
002
Page 195 of 1871